NULL pointer dereference in Linux kernel - CVE-2026-93261
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a missing null check in __lock_set_class() when register_lock_class() returns NULL. A local user can cause lock class registration to fail to cause a denial of service.
Lock class registration can fail when the lock class pool is exhausted, graph_lock() fails, or key validation fails.
Affected software
How to mitigate CVE-2026-93261
External References
- https://git.kernel.org/stable/c/59a5c7dd331a3dab48100e1ef8e9bb4f9132a2b2
- https://git.kernel.org/stable/c/5c3bff6cf26e6a54fbf8b893a879c32824d2d50d
- https://git.kernel.org/stable/c/7577e00b9ab506202b9f1a33de3cc8cc6413a4db
- https://git.kernel.org/stable/c/9be10f49dfc2e4b472b3a5f346483b67374774b8
- https://git.kernel.org/stable/c/b2113dcd8238bf00ce37a34e67b29cf31d32a545
- https://git.kernel.org/stable/c/e7c69c6695d84220847cca62a45e879e71e79e9d
- https://git.kernel.org/stable/c/f56e54fd24f05e9de528fcb77f6084f80c8066ce
- https://git.kernel.org/stable/c/f6093ff67ea6e347574819ed23e96e0f82a25ffc